Main Menu
Home
Bookmark
Contact Us



 
Codr.140 Viruses Information

Name: Codr.140
Category: Viruses
Description: Details
Codr.1402

This is a very dangerous memory resident partly encrypted parasitic virus. It hooks INT 10h and 21h, and writes itself to the end of COM and EXE files (except COMMAND.COM) that are executed or opened. When the DRWEB.EXE file is executed, the virus disables its INT 21h hooker, hooks INT 22h (program terminate address), waits for the moment the program exits, and re-hooks INT 21h.
Depending on the current date, the virus runs one of its trigger routines. On Friday the 13th of any month, the virus erases data on the hard drive. On the 21st of any month at 12:xx, the virus reboots the computer.
The virus contains the text:
COMMAND.COM DRWEB.EXE .COM .EXE



Top Viruses Visited Pages:
Invader. - 234 visits
not-a-virus:RiskWare.Tool.RegPatch. - 72 visits
Worm.P2P.Harex. - 65 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 59 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 47 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Methyl.88
Kvapavka.87
TSM.553
Win32.Cham
Awake.109
Macro.Word97.Komco
Ungame_II.82
Macro.Word.NO
Claudia.877
Macro.Excel.Dado.


 


© 2006-2008 spyware32.com - Privacy Policy